CVE-2026-61686
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 4, 2026 · Last modified: Sep 4, 2026 · CWE-502
Not enough EPSS history yet.
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-52777——
———YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.13hCVE-2026-197956.2 MED—
——0Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.16hCVE-2026-848349.8 CRI—
——0Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.2dCVE-2026-847539.8 CRI—
——0Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.11hCVE-2026-847528.8 HIG—
——0Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.2dCVE-2026-84832—46.9%
——14SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.20h